-
Rapid7’s Metasploit Framework is set to add an exploit module targeting the actively exploited chain of vulnerabilities affecting PaperCut MF and PaperCut NG. This addition will provide public offensive tooling for a security emergency involving …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenClaw has launched version 2.0, offering a major overhaul of its AI-agent platform. This update emphasizes streamlined deployment, a rebuilt browser experience, collaborative cloud sessions, and enhanced security for credentials and connected servic…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Shai-Hulud supply-chain attack dubbed Trinitite has compromised the npm package @7nohe/openapi-react-query-codegen, a TanStack Query code-generation library with more than 150,000 weekly downloads. The malicious releases deploy an evolved Mini Sh…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming “Microsoft Defender Antivirus is turned off,” even though the protection is still operational. These alerts m…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S. retailer could be exploited to enable remote code execution (RCE) on the company’s backend infrastructure through its public-facing mobile application…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Android 17 introduces a new set of network security controls to reduce cellular downgrade attacks, protect local networks, and limit metadata exposure during encrypted web sessions. This update includes carrier-managed 2G shutdown capabilities designed…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Magecart campaign dubbed HexMage has compromised more than 40 e-commerce storefronts across at least 15 countries, using Ethereum smart contracts as a resilient delivery mechanism for payment-card skimmers. The operation blends traditional client-sid…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on the local network to reset the administrator password and retrieve wireless configuration info…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted development, browser credential theft, and aggressive persistence designed to survive incomplete remediation….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Composer users are urged to update their software following the disclosure of a path-traversal vulnerability. This flaw could allow a malicious or compromised PHP package to change file permissions outside of its own installation directory. The vulnera…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


